Data Processing Addendum
Last updated: July 21, 2026
This Data Processing Addendum (“DPA”) forms part of the Terms of Use or other agreement (“Agreement”) between Berryhill Consulting LLC (“Rekonix”) and the customer identified in the account or order (“Customer”). It applies when Rekonix processes Customer Personal Data on Customer’s behalf. Capitalized terms not defined here have the meaning in the Agreement.
1. Definitions
- Applicable Data Protection Law means privacy and data-protection law applicable to the processing under the Agreement.
- Customer Personal Data means personal information or personal data contained in Your Data that Rekonix processes on Customer’s behalf.
- Controller, processor, business, service provider, consumer, and data subject have the meanings provided by applicable law.
- Security Incident means unauthorized access to, acquisition, alteration, loss, destruction, or disclosure of Customer Personal Data in Rekonix’s custody or control. It excludes unsuccessful attempts that do not compromise data.
- Subprocessor means a third party appointed by Rekonix to process Customer Personal Data on Customer’s behalf.
2. Roles and instructions
As between the parties, Customer is the controller or business and Rekonix is the processor or service provider for Customer Personal Data. Customer instructs Rekonix to process the data to provide, secure, maintain, and support the Service; perform the Agreement; comply with Customer’s documented use and configuration; and comply with law. The Agreement, this DPA, account settings, and authorized support requests are Customer’s documented instructions. Rekonix will notify Customer if an instruction appears to violate applicable law, unless prohibited from doing so.
3. Customer obligations
Customer is responsible for lawful instructions; the accuracy and necessity of Customer Personal Data; required notices, consents, and legal bases; user permissions; responding to individuals; and determining whether the Service is appropriate for Customer’s legal and regulatory obligations. Customer will not submit PHI until a BAA is effective or use the Service for data subject to a restriction Rekonix has not agreed to support.
4. Processing details
| Subject | Provision of the Rekonix cloud accounting Service and customer-selected modules and integrations. |
|---|---|
| Duration | The Agreement plus the limited retention and deletion period described in the Privacy Policy and this DPA. |
| Nature and purpose | Collection, hosting, organization, calculation, retrieval, consultation, transmission, reconciliation, reporting, support, security, export, deletion, and other processing directed through the Service. |
| People | Customer users and contacts; customers; vendors; workers; firm clients; donors; owners; tenants; patients when a BAA is effective; and other people represented in Customer’s records. |
| Data | Identity and contact data; roles; business and financial records; transaction and bank data; billing and payment references; tax and government identifiers; correspondence and documents; device, log, and audit data; and module-specific records selected by Customer. |
| Sensitive data | Financial-account information, tax identifiers, payment instructions, precise business records, authentication and portal tokens, and health information only under an effective BAA. |
5. Confidentiality and personnel
Rekonix will limit access to personnel and contractors who need it for the Service, bind them to confidentiality, and provide appropriate privacy and security direction. Rekonix remains responsible for their compliance with this DPA to the extent required by law and contract.
6. Security
Rekonix will maintain risk-appropriate safeguards, including as applicable:
- Encryption in transit and managed encryption at rest, with application-layer encryption for selected high-risk tokens, payment references, and documents.
- Tenant-scoped authorization, role controls, protected production access, secrets management, and authentication through a managed provider.
- Audit evidence for material record and administrative actions, secure development practices, dependency maintenance, backups, and recovery procedures.
- Incident investigation, containment, remediation, and legally required notification procedures.
- Vendor assessment proportionate to the provider’s access and contractual data-protection commitments.
Customer acknowledges that security is shared and will protect its users, devices, exports, credentials, integrations, and role configuration.
7. Subprocessors
Customer generally authorizes the Subprocessors on the Subprocessor List and customer-directed optional providers enabled through the Service. Rekonix will require a Subprocessor to protect Customer Personal Data through written terms appropriate to its processing. Rekonix remains responsible for its Subprocessors to the extent required by applicable law and this DPA.
Rekonix will post material changes to the list and, where appropriate, provide notice at least 30 days before a new Subprocessor begins material processing. Customer may object during that period on reasonable data-protection grounds. The parties will work in good faith on a commercially reasonable solution. If none is available, Customer may stop using the affected feature; a refund, if any, is limited to prepaid unused fees for that feature.
8. Individual requests
Taking into account the nature of processing, Rekonix will provide reasonable assistance through available product controls or support so Customer can respond to valid requests for access, correction, deletion, portability, restriction, or appeal. If Rekonix receives a request concerning Customer Personal Data, it may direct the requester to Customer unless law requires Rekonix to respond directly.
9. Security Incidents
Rekonix will notify Customer without undue delay after confirming a Security Incident affecting Customer Personal Data. Notice will include available information reasonably needed for Customer’s obligations, such as the nature of the incident, affected data, likely consequences, and mitigation. Rekonix will investigate, contain, remediate, and reasonably cooperate. Notification is not an admission of fault or liability.
10. Assessments, regulators, and audits
Rekonix will provide information reasonably necessary to demonstrate compliance and assist with legally required data-protection assessments and regulator consultations, considering the nature of the Service and information available to Rekonix. Customer will first use current documentation, certifications, and written responses. No more than once annually, unless required by a regulator or following a Security Incident, Customer may request a scoped audit by an independent professional under confidentiality, during normal hours, without accessing another customer’s data or unreasonably disrupting the Service. Customer bears its audit costs.
11. Return and deletion
During the account term, Customer may use available exports. On verified closure or written instruction, Rekonix will delete or deidentify Customer Personal Data within a reasonable period, except data retained in protected backups until normal expiry or retained as required by law, security, fraud prevention, dispute, tax, or accounting obligations. Retained data remains protected and is not used for another purpose. Rekonix will confirm the applicable schedule on request.
12. International transfers
Customer authorizes processing in the United States and locations identified for approved providers. If a legally required transfer mechanism applies, the parties will incorporate the then-current standard contractual clauses or other valid mechanism, with Customer as exporter and Rekonix as importer as appropriate. Rekonix will implement supplementary measures reasonably required for the Service.
13. United States state privacy terms
To the extent a U.S. state privacy law applies, Rekonix acts as Customer’s service provider, processor, or contractor for Customer Personal Data. Rekonix will not sell or share it for cross-context behavioral advertising; retain, use, or disclose it outside the business purposes in the Agreement except as permitted by law; combine it with personal information received from another source except as permitted by law; or attempt to reidentify deidentified data. Customer may take reasonable steps to verify compliance and require remediation.
14. Order of precedence and liability
An executed BAA controls for PHI. This DPA controls over conflicting general privacy-processing terms in the Agreement. The Agreement’s limitations and remedies apply to this DPA except where applicable law or an executed BAA prohibits a limitation.
15. Contact and execution
This DPA is accepted with the Agreement. A countersigned copy or additional transfer documentation may be requested at support@rekonix.com.